eupolicy.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
This Mastodon server is a friendly and respectful discussion space for people working in areas related to EU policy. When you request to create an account, please tell us something about you.

Server stats:

216
active users

#localmess

0 posts0 participants0 posts today

#Passwort - der Podcast von #heise #security: Lokale Sauereien von #Meta und #Yandex
#Browser #Facebook
#WhatsApp #DSGVO

Meta und Yandex sind bei #Trackingmethoden erwischt worden, die weit über das Übliche hinausgehen. Christopher und Sylvester sehen sich die Publikation "
#LocalMess" an. Darin dokumentieren Forscher #Tracking-Tricks dieser Firmen, die den Nutzerwünschen explizit zuwiderlaufen, Securitymaßnahmen untergraben und #Kommunikation verschleiern.

Die Hosts haben Mühe, noch einen Unterschied zum Vorgehen typischer #Malware zu sehen.

Webseite der Episode:
passwort.podigee.io/34-lokale-

Mediendatei:
audio.podigee-cdn.net/1973369-

@ulrichkelber

echt guter Podcast zum Thema #LocalMess von @heisec , wie #Meta und Yandex mit ihren Apps als Schadsoftware agiert haben.

Die Apps #Facebook & #Instagram & #Yandex haben Schutzmaßnahmen des Betriebssystems umgangen, also von #Android. So konnten alle Aktivitäten im Browser getrackt werden, solange das passende Trackingscript auf der Website ausgespielt wird.

Apps deaktivieren / Werbeblocker installieren.

passwort.podigee.io/34-lokale-

Companies are pushing non-stop for users to move from web apps to phone apps. They justify the push saying phone apps are more secure. But that's a blatant lie. They want you to move to phone apps so they have a lot more control over you, and can drain a lot more information about you. The recent #LocalMess misbehavior from #Meta is just one more example showing this: if you install their app, the OS will allow them doing many things the web browser won't. localmess.github.io/

localmess.github.ioCovert Web-to-App Tracking via Localhost on Android

#Meta #Facebook and #Yandex are always looking for new ways to spy on you and track you. #LocalMess is the latest in a long line of abusive methods to gather your private data. Having their mobile app installed gives them super powers. Uninstall it. If you must use these services, do not use their app, keep it in the browser, or even better, use a wrapper app, like

* f-droid.org/packages/it.rignan
* f-droid.org/packages/us.spotco

Here is a nice technical write up:
localmess.github.io/

f-droid.orgSlimSocial for Facebook | F-Droid - Free and Open Source Android App RepositoryBrowse Facebook

#Zuckerberg’s privacy pledge revealed as ineffectual

Millions of websites are leaking your private information to #Meta, the parent company of #Facebook, #Instagram, etc. By hacking #Android browser features in ways that were never intended, Meta is tracking you all the way around the web—with no disclosure nor oversight.

Incognito mode doesn’t stop it; neither does blocking 3rd-party cookies. Russian social giant #Yandex is doing it too.

As soon as researchers disclosed the #LocalMess problem, Meta stopped it—for now. In #SBBlogwatch, we go live in a cave.

securityboulevard.com/2025/06/

Security Boulevard · Meta’s Secret Spyware: ‘Local Mess’ Hack Tracks You Across the WebFarcebok: Zuckerberg’s privacy pledge revealed as ineffectual

#Meta is seriously concerning 👿

Their apps open local ports on #Android, while their #tracking pixels, embedded in thousands of websites, connect to these ports and gather information about users. This effectively bypasses #privacy measures such as private browsing or clearing cookies, making users personally identifiable on websites that use those pixels.

Although it appears they have stopped this technique after it was uncovered, it still reveals Meta's true intentions, imho.

La pillada que le acaban de hacer a Meta espiando y desanonimizando a usuarios de Android es tremenda. Ojalá se lleven una multa descomunal, pero dudo que eso pase o si pasa dudo que valga para cambiar nada. Poca opción nos queda como usuarios más allá de dejar de usar aplicaciones de este tipo de empresas y bloquear todos los trackers que podamos en las webs que visitemos.

localmess.github.io/

localmess.github.ioCovert Web-to-App Tracking via Localhost on Android